SBA Security Advisory – DFIR-IRIS Missing Brute Force Protection (CVE-2026-16971, CVE-2026-18362)
Vulnerability Overview
The IRIS web application in version 2.4.26 and possibly others does not protect its MFA validation (CVE-2026-16971) and user authentication (CVE-2026-18362) against brute-force attacks.
- Type of Vulnerability: Missing Brute Force Protection
- Fixed in Version: not currently available
- CVE ID: CVE-2026-16971, CVE-2026-18362
- CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- CVSS Base Score: 5.9 (Medium)
Recommended Countermeasure
We are not aware of a fix yet. Please contact the vendor.
Link
Credits
Michael Koppmann (SBA Research)
Mathias Tausig (SBA Research)
The discovery of this vulnerability was made possible through support from CYSSDE and the European Union.
